1. 程式人生 > >思科ASA防火墻域路由器IPSec ×××

思科ASA防火墻域路由器IPSec ×××

onf ip add nsf size fig 51cto ipsec 思科 form

思科ASA防火墻域路由器IPSec ×××

技術分享圖片

1:防火墻端口配置
ciscoasa(config)#int e0/0
ciscoasa(config-if)# ip add 192.168.1.254 255.255.255.0
ciscoasa(config-if)# no shut
ciscoasa(config-if)# nameif inside
ciscoasa(config-if)# security-level 100
ciscoasa(config-if)# int e0/1
ciscoasa(config-if)# ip add 100.0.0.1 255.255.255.0
ciscoasa(config-if)# no shut

ciscoasa(config-if)# nameif outside
ciscoasa(config-if)# exit
2:路由器端口配置
R2#conf t
R2(config)#int f0/0
R2(config-if)#ip add 100.0.0.1 255.255.255.0
R2(config-if)#no shut
R2(config-if)#int f0/1
R2(config-if)#ip add 192.168.2.254 255.255.255.0
R2(config-if)#no shut
R2(config-if)#exit
3:ISP基本配置
R1#conf t
R1(config)#int f0/0
R1(config-if)#ip add 100.0.0.2 255.255.255.0
R1(config-if)#no shut
R1(config-if)#int f0/1
R1(config-if)#ip add 100.0.0.2 255.255.255.0
R1(config-if)#no shut
R1(config-if)#
4:路由的設置
1)防火墻路由設置
ciscoasa(config)# route outside 0 0 100.0.0.2
2)分支路由器路由設置
R2(config)#ip route 0.0.0.0 0.0.0.0 100.0.0.2
5:防火墻***配置
ciscoasa(config)# crypto isakmp enable outside
ciscoasa(config)# crypto isakmp policy 1
ciscoasa(config-isakmp-policy)# encryption aes
ciscoasa(config-isakmp-policy)# hash sha
ciscoasa(config-isakmp-policy)# group 2
ciscoasa(config-isakmp-policy)# authentication pre-share
ciscoasa(config-isakmp-policy)# exit
ciscoasa(config)# crypto isakmp key benet address 100.0.0.1
ciscoasa(config)# access-list 200 extended permit ip 192.168.1.0 255.255.255.0 192.168.2.0 255.255.255.0
ciscoasa(config)# crypto ipsec transform-set benet-set esp-aes
ciscoasa(config)# crypto map benet-map 1 match address 200
ciscoasa(config)# crypto map benet-map 1 set peer 100.0.0.1
ciscoasa(config)# crypto map benet-map 1 set transform-set benet-set
ciscoasa(config)# crypto map benet-map interface outside
6:路由器***配置
R2(config)#crypto isakmp policy 1
R2(config-isakmp)#hash sha
R2(config-isakmp)#encryption aes
R2(config-isakmp)#authentication pre-share
R2(config-isakmp)#group 2
R2(config-isakmp)#exit
R2(config)#crypto isakmp key 6 benet address 100.0.0.1
R2(config)#access-list 100 permit ip 192.168.2.0 0.0.0.255 192.168.1.0 0.0.0.255
R2(config)#crypto ipsec transform-set benet-set esp-aes
R2(cfg-crypto-trans)#exit
R2(config)#crypto map benet-map 1 ipsec-isakmp
R2(config-crypto-map)#set peer 100.0.0.1
R2(config-crypto-map)#match address 100
R2(config-crypto-map)#set transform-set benet-set
R2(config-crypto-map)#exit
R2(config)#int f0/0
R2(config-if)#crypto map benet-map
R2(config-if)#
R2(config-if)#end
R2#debug crypto isakmp

思科ASA防火墻域路由器IPSec ×××